STIX2 json for 2026-07-13

STIX2 json for all bruteforce attempts for 2026-07-13

Last Updated: 11:07 UTC

Download STIX2 json File

']", "pattern_type": "stix", "valid_from": "2026-07-13T00:00:00.000Z", "valid_until": "2026-08-12T23:59:59.000Z", "kill_chain_phases": [{"kill_chain_name": "lockheed-martin-cyber-kill-chain", "phase_name": "exploitation"}], "external_references": [{"source_name": "jamesbrine.com.au Threat Intelligence", "description": "Daily threat feed", "url": "https://jamesbrine.com.au/2026-07-13-stix2-json-feed/"}], "labels": ["sensor:digitaloceanlondon", "protocol:ftp", "protocol:git", "protocol:mssql", "protocol:mysql", "protocol:ntp", "protocol:portscan", "protocol:redis", "protocol:sip", "protocol:snmp", "protocol:ssh", "protocol:telnet", "protocol:web"], "created_by_ref": "identity--8f46cf6a-622e-4127-bbdd-968d59ea87e0", "created": "2026-07-14T11:00:01.685Z", "modified": "2026-07-14T11:00:01.685Z", "object_marking_refs": ["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"]}, {"type": "indicator", "spec_version": "2.1", "id": "indicator--6d9d3094-3e72-40c4-ac06-6d6a5d5def1d", "name": "Malicious Host", "description": "Observed: FTP, GIT, MSSQL, MYSQL, NTP, PORTSCAN, REDIS, SIP, SNMP, SSH, TELNET, WEB activity. Sensors: digitaloceanlondon", "indicator_types": ["malicious-activity"], "pattern": "[ipv4-addr:value = '']", "pattern_type": "stix", "valid_from": "2026-07-13T00:00:00.000Z", "valid_until": "2026-08-12T23:59:59.000Z", "kill_chain_phases": [{"kill_chain_name": "lockheed-martin-cyber-kill-chain", "phase_name": "exploitation"}], "external_references": [{"source_name": "jamesbrine.com.au Threat Intelligence", "description": "Daily threat feed", "url": "https://jamesbrine.com.au/2026-07-13-stix2-json-feed/"}], "labels": ["sensor:digitaloceanlondon", "protocol:ftp", "protocol:git", "protocol:mssql", "protocol:mysql", "protocol:ntp", "protocol:portscan", "protocol:redis", "protocol:sip", "protocol:snmp", "protocol:ssh", "protocol:telnet", "protocol:web"], "created_by_ref": "identity--8f46cf6a-622e-4127-bbdd-968d59ea87e0", "created": "2026-07-14T11:00:01.685Z", "modified": "2026-07-14T11:00:01.685Z", "object_marking_refs": ["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"]}, {"type": "indicator", "spec_version": "2.1", "id": "indicator--1a2b4b42-9e14-4121-bfcb-e870b5108268", "name": "Malicious Host", "description": "Observed: FTP, GIT, MSSQL, MYSQL, NTP, PORTSCAN, REDIS, SIP, SNMP, SSH, TELNET, WEB activity. Sensors: digitaloceanlondon", "indicator_types": ["malicious-activity"], "pattern": "[ipv4-addr:value = '']", "pattern_type": "stix", "valid_from": "2026-07-13T00:00:00.000Z", "valid_until": "2026-08-12T23:59:59.000Z", "kill_chain_phases": [{"kill_chain_name": "lockheed-martin-cyber-kill-chain", "phase_name": "exploitation"}], "external_references": [{"source_name": "jamesbrine.com.au Threat Intelligence", "description": "Daily threat feed", "url": "https://jamesbrine.com.au/2026-07-13-stix2-json-feed/"}], "labels": ["sensor:digitaloceanlondon", "protocol:ftp", "protocol:git", "protocol:mssql", "protocol:mysql", "protocol:ntp", "protocol:portscan", "protocol:redis", "protocol:sip", "protocol:snmp", "protocol:ssh", "protocol:telnet", "protocol:web"], "created_by_ref": "identity--8f46cf6a-622e-4127-bbdd-968d59ea87e0", "created": "2026-07-14T11:00:01.685Z", "modified": "2026-07-14T11:00:01.685Z", "object_marking_refs": ["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"]}, {"type": "indicator", "spec_version": "2.1", "id": "indicator--e122d512-abb7-4a2b-835c-09316f9c7105", "name": "Malicious Host", "description": "Observed: FTP, GIT, MSSQL, MYSQL, NTP, PORTSCAN, REDIS, SIP, SNMP, SSH, TELNET, WEB activity. Sensors: digitaloceanlondon", "indicator_types": ["malicious-activity"], "pattern": "[ipv4-addr:value = '']", "pattern_type": "stix", "valid_from": "2026-07-13T00:00:00.000Z", "valid_until": "2026-08-12T23:59:59.000Z", "kill_chain_phases": [{"kill_chain_name": "lockheed-martin-cyber-kill-chain", "phase_name": "exploitation"}], "external_references": [{"source_name": "jamesbrine.com.au Threat Intelligence", "description": "Daily threat feed", "url": "https://jamesbrine.com.au/2026-07-13-stix2-json-feed/"}], "labels": ["sensor:digitaloceanlondon", "protocol:ftp", "protocol:git", "protocol:mssql", "protocol:mysql", "protocol:ntp", "protocol:portscan", "protocol:redis", "protocol:sip", "protocol:snmp", "protocol:ssh", "protocol:telnet", "protocol:web"], "created_by_ref": "identity--8f46cf6a-622e-4127-bbdd-968d59ea87e0", "created": "2026-07-14T11:00:01.685Z", "modified": "2026-07-14T11:00:01.685Z", "object_marking_refs": ["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"]}, {"type": "indicator", "spec_version": "2.1", "id": "indicator--8943cbca-b356-49c0-86d8-ec5f48e5958f", "name": "Malicious Host", "description": "Observed: FTP, GIT, MSSQL, MYSQL, NTP, PORTSCAN, REDIS, SIP, SNMP, SSH, TELNET, WEB activity. Sensors: digitaloceanlondon", "indicator_types": ["malicious-activity"], "pattern": "[ipv4-addr:value = ';

Share on: